2026 CVE Vulnerabilities

43,564 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22656Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22655Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22654Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22653Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22652Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22651Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-12624MEDIUM4.3Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra...
CVE-2026-72726MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u...
CVE-2026-72725MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo...
CVE-2026-72724MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c...
CVE-2026-72723MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano...
CVE-2026-72722MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_...
CVE-2026-72721MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec...
CVE-2026-72720MEDIUM6.4Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse...
CVE-2026-72719MEDIUM6.7Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf...
CVE-2026-72718HIGH7goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system...
CVE-2026-66738HIGH8.8SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint ...
CVE-2026-56620MEDIUM4.3HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor...
CVE-2026-48158CRITICAL9.3use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34,...
CVE-2026-48048HIGH7.5XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Sta...
CVE-2026-47754CRITICAL9.3Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19...
CVE-2026-72761MEDIUM6.9The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses afte...
CVE-2026-72760MEDIUM5.3Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe...
CVE-2026-72759MEDIUM6.9In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization...
CVE-2026-19433HIGH8.6Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now